Skip to main content

Vendor/product archive

nagios / log_server CVEs

Beta · best-effort

23 CVEs tagged to nagios / log_server3 Critical, 9 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2025-34323

Published Nov 17, 2025

Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directorie…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34322

Published Nov 17, 2025

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature i…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34298

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid va…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34277

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an i…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-34274

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. If an atta…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-34273

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application di…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34272

Published Oct 30, 2025

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboar…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34271

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted c…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34270

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a res…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58273

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web user (or the…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-7323

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input ma…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-7322

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endp…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-7321

Published Oct 30, 2025

Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for the output context…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36858

Published Oct 30, 2025

Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host Lists pages. Insu…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-15049

Published Oct 30, 2025

Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Logs table. Untrusted log conten…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-44824

Published Oct 7, 2025

Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/index.php/api/system/stop?subsy…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-44823

Published Oct 7, 2025

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-29471

Published Apr 15, 2025

Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-35479

Published Jul 30, 2021

Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35478

Published Jul 30, 2021

Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affect…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25385

Published Jan 20, 2021

Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact use…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-16157

Published Jul 30, 2020

A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15898

Published Sep 3, 2019

Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1